<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is best process of sending logs from Splunk to syslogng server ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325918#M60601</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
We are planning to forward Windows events logs from Splunk to RSA.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/581066/how-splunk-can-send-data-to-third-party-system-spe.html"&gt;https://answers.splunk.com/answers/581066/how-splunk-can-send-data-to-third-party-system-spe.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We already did the three approaches mentioned above and they were not working. We are trying to send data from Splunk to syslogng server and from there -- RSA collects data?&lt;/P&gt;

&lt;P&gt;Is there any process of sending logs from Splunk to syslogng server?&lt;/P&gt;

&lt;P&gt;Any help, please?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2017 13:15:30 GMT</pubDate>
    <dc:creator>splunker969</dc:creator>
    <dc:date>2017-10-25T13:15:30Z</dc:date>
    <item>
      <title>What is best process of sending logs from Splunk to syslogng server ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325918#M60601</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
We are planning to forward Windows events logs from Splunk to RSA.&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/581066/how-splunk-can-send-data-to-third-party-system-spe.html"&gt;https://answers.splunk.com/answers/581066/how-splunk-can-send-data-to-third-party-system-spe.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;We already did the three approaches mentioned above and they were not working. We are trying to send data from Splunk to syslogng server and from there -- RSA collects data?&lt;/P&gt;

&lt;P&gt;Is there any process of sending logs from Splunk to syslogng server?&lt;/P&gt;

&lt;P&gt;Any help, please?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 13:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325918#M60601</guid>
      <dc:creator>splunker969</dc:creator>
      <dc:date>2017-10-25T13:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: What is best process of sending logs from Splunk to syslogng server ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325919#M60602</link>
      <description>&lt;P&gt;You can take a look at &lt;A href="https://splunkbase.splunk.com/app/1847/"&gt;this app&lt;/A&gt; and its documentation to see if that would help you meet your needs. It's a search-based approach to forward data via SYSLOG specifically built for 3rd-party SIEM integrations.&lt;/P&gt;

&lt;P&gt;That aside: If you followed the documentation &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Forwarding/Forwarddatatothird-partysystemsd#Syslog_data"&gt;here&lt;/A&gt; and it didn't work for you, can you explain what issue you were experiencing? Maybe we can collectively get you on the right track.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 18:23:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325919#M60602</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-25T18:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: What is best process of sending logs from Splunk to syslogng server ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325920#M60603</link>
      <description>&lt;P&gt;Hi SSievert ,&lt;/P&gt;

&lt;P&gt;We are now seeing traffic leave our Indexers when monitoring the interface via tcpdump . However RSA is not able to parse the data, even though the field mappings appear correct and in line with CEF standards template.&lt;/P&gt;

&lt;P&gt;We suspect this may be because there is no priority value at the beginning of these events (which RSA needs apparently&lt;/P&gt;

&lt;P&gt;From what I can see, the Splunk app for CEF configures the output.conf to use tcpout as the processor (instead of syslog). Could you confirm if this is correct and if so, would it be possible to change this to syslog?&lt;/P&gt;

&lt;P&gt;Would really appreciate any help and support you can provide in this matter@ssievert  &lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 18:00:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325920#M60603</guid>
      <dc:creator>splunker969</dc:creator>
      <dc:date>2017-10-30T18:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: What is best process of sending logs from Splunk to syslogng server ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325921#M60604</link>
      <description>&lt;P&gt;Can you share the outputs.conf? &lt;BR /&gt;
Do you have a section that looks like this:&lt;BR /&gt;
    [syslog:myRSAservers]&lt;BR /&gt;
    type=tcp&lt;BR /&gt;
    priority=nn&lt;BR /&gt;
    etc.&lt;BR /&gt;
as documented &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/outputsconf#Syslog_output----"&gt;here&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 19:08:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325921#M60604</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-30T19:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: What is best process of sending logs from Splunk to syslogng server ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325922#M60605</link>
      <description>&lt;P&gt;I believe app only build to send data tcp routing @ssievert .Also please find below outputs.conf&lt;BR /&gt;
[tcpout:RSA_Netwitness]&lt;BR /&gt;
Server =ip:port&lt;BR /&gt;
blockONClonning= 5&lt;BR /&gt;
sendCookedData=false&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 20:02:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-best-process-of-sending-logs-from-Splunk-to-syslogng/m-p/325922#M60605</guid>
      <dc:creator>splunker969</dc:creator>
      <dc:date>2017-10-30T20:02:34Z</dc:date>
    </item>
  </channel>
</rss>

